One-time exchange token to hand to the application's auth service.
ISO session expiry.
OptionalhostnamesThe application's full hostname set (generated AND custom domains).
Open-redirect guard: the webapp validates an access link's return
destination against this set before bouncing the exchange token to it.
Optional for compatibility with backends that predate 2026-08-25.
Result of redeeming a short code (the backend mints a session + exchange token).